CRITICAL

CVE-2024-50623

Cleo Harmony 2024-10-28 CVSS v3.1
CVSS
9.8
KEV

Description

In Cleo Harmony before 5.8.0.21, VLTrader before 5.8.0.21, and LexiCom before 5.8.0.21, there is an unrestricted file upload and download that could lead to remote code execution.

Summary dbcve.org

This is an unrestricted file upload and download vulnerability in Cleo Harmony, VLTrader, and LexiCom (all versions before 5.8.0.21) that allows attackers to upload malicious files to the system without proper restrictions, potentially leading to remote code execution.

Mitigation

Upgrade to version 5.8.0.21 or later for all affected products. If immediate patching is not possible, implement network segmentation and restrict file upload functionality to trusted sources only.

Weakness (CWE)

CWE-434 Unrestricted File Upload

EPSS Score

98.61%
Probability of exploitation in next 30 days
99.9th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE